FB pixel

What is China’s new data privacy law hoping to achieve?

Categories Biometrics News
What is China’s new data privacy law hoping to achieve?
 

The first of November marked the beginning of an apparent regulatory crackdown on data privacy violations in China, as the country’s first comprehensive privacy law (the Personal Information Protection Law) came into effect, leading to a surging demand for data protection specialists and seeing major corporations departing.

The new law, which has been compared to Europe’s GDPR by non-for-profit international privacy community IAPP (International Association of Privacy Professionals), will not only see an increase in data security, sovereignty and personal information rights, but will reshape how companies in China do business, the organization writes.

“When you look at PIPL, it is really focusing on protecting individuals, society, and national security—because of the unique Chinese political system,” says Alexa Lee, a senior manager of policy at the Information Technology Industry Council and an associate editor of Stanford University’s DigiChina project, which has been translating the PIPL into English.

The law aims to enhance cybersecurity along with complementing the country’s national security interests; therefore, companies wanting to share data outside of China must also now go through a national security review. This also goes for companies holding data on more than a million people (to send abroad), likewise for any reasonable-sized company operating in and out of China.

“If European data protection laws are grounded in fundamental rights and U.S. privacy laws are grounded in consumer protection, Chinese privacy law is closely aligned with, and I would even say grounded in, national security,” says Omer Tene, a partner specializing in data, privacy, and cybersecurity at law firm Goodwin. Reviews may​​ include laying out why data is being transferred out of China, the types of information being sent, and the risks of doing so.

Employing a data protection officer for companies is mandatory, and if PIPL laws are breached, applicable fines can be up to $7.8 million or 5 percent of a firm’s annual revenue—roughly equivalent to GDPR’s $23 million and 4 percent thresholds.

This said, government access of citizens’ personal data will not be affected by PIPL. Chinese citizens will remain under some form of surveillance, says Wired. Government use of digital surveillance is a “take it or take it” proposition. There is no significant government consideration about how citizens feel about the blanket biometric surveillance throughout the nation. Last month however saw reports that China has approved its first AI industry ethics guidelines, which if grounded in the law could surpass the West in establishing governance rules.

Wired highlights PIPL’s potential for influence on neighboring countries which are still developing their own data protection policies, DigiChina’s Lee is concerned that other Asian countries may follow suit using data localization measures, which are already being seen in draft laws in India and Vietnam.

While IAPP compares the key types of personal information rights under the GDPR and the PIPL such as the right to erasure, right to data portability and right not to be subject to automated decision making, it remains uncertain how such rights under PIPL might be interpreted in practice and what effects PIPL will have on Chinese citizens.

Article Topics

 |   |   |   |   |   |   |   | 

Latest Biometrics News

 

DHS launches $440M government-wide biometric capture procurement

The U.S. Department of Homeland Security (DHS) has launched a government-wide procurement that could standardize how federal agencies capture fingerprints,…

 

Clearview AI prototype points to next phase of facial recognition: identity intelligence

Clearview AI has developed an experimental AI tool that could extend a facial recognition search into broader automated research on…

 

AI agents change the identity security question in the middle of enterprises’ answer

The digital identity industry has been diligently working on how to authenticate people without risking exposure to fraud attacks, particularly…

 

The next bottleneck for African digital identity is infrastructure, not software

Africa’s next wave of digital identity investment may have surprisingly little to do with biometrics, wallets or credentials. In early…

 

TrustED tests whether Europe’s digital identity model can preserve privacy in the real world

Europe’s digital identity ambitions are approaching an important deadline. By the end of 2026, EU Member States are expected to…

 

A biometric system can be accurate and still fail an accessibility test

By Joshua W.J. Brown Biometric authentication has mature ways to talk about comparison error. That is exactly why accessibility failures…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Market Intelligence

Featured Company

Biometric Update Podcast

Most Read This Week

White Papers

Latest Webinars

Biometrics Industry Events